Difference between revisions of "Edit permissions"

From ICA-AtoM
Jump to navigation Jump to search
Line 1: Line 1:
 
[[Main Page]] > [[User manual]] > [[Administer]] > Edit permissions
 
[[Main Page]] > [[User manual]] > [[Administer]] > Edit permissions
 
When refining user permissions, it is often useful to start with the group to which the user belongs. You can refine permissions for the group, then add users to the group, all of whom will inherit the modified permissions. '''To lean how to refine user permissions, follow the steps in scenario one, below. Then try some more of the scenarios listed at the bottom of this page, all of which relate to the user created in scenario one.'''
 
  
 
* You should have two or more archival institutions in your system, with several hierarchical descriptions attached and some digital objects uploaded, in order to fully test the scenarios on this page
 
* You should have two or more archival institutions in your system, with several hierarchical descriptions attached and some digital objects uploaded, in order to fully test the scenarios on this page
Line 11: Line 9:
 
<ol>
 
<ol>
  
[[Image:permissions1.png|500px|right|thumb|Fig.1. Default permissions for contributor group in show screen]]
+
When refining user permissions you can begin by creating a User, but do not assign them to a unique User group. Leave this blank and it will automatically assign the User as an authenticated user. (See fig.1)
 
 
<li>
 
 
 
In the main menu bar, go to admin > groups > contributor. Click on Archival description permissions in the grey menu above the title bar. Your screen will show the default "Grant" permissions for the contributor group - i.e. it shows you everything the user is permitted to do (see fig.1)
 
 
 
<div class="note">
 
  
* The contributor group inherits some of its settings from its parent group, authenticated (which is all users who have successfully logged-in)
+
[[Image:singlerep_user01.png|500px|right|thumb|Fig.1. Leave group field blank. User automatically becomes an authenticated user.]]
* Any permission that has not been "granted" by the current group (contributor) or its parent group (authenticated) is considered "denied" by default. In other words the default for the system is to deny permission unless a rule explicitly grants it
 
  
 
</div>
 
</div>
Line 26: Line 17:
 
</li>
 
</li>
  
[[Image:permissions2.png|500px|right|thumb|Fig.2. Default permissions for contributor group in edit screen]]
+
In order to restrict permissions to descriptions of a particular institution, we need to go to Admin menu > Users. Select the User you want to restrict to specific repository permissions. (See fig.2)
 
 
<li>
 
 
 
Click Edit. In the edit screen, you will get a better sense of the group's permission settings (see fig.2) . The contributor has the following permissions:
 
* Read: Grant (inherited from authenticated group)
 
* Create: Grant
 
* Update: Grant
 
* Delete: Deny (default deny)
 
* View draft: Grant
 
* Publish: Deny (default deny)
 
* Access master digital object: Grant
 
* Access reference digital object: Grant (inherited from authenticated group).
 
 
 
In other words, any user belonging to the contributor group automatically has been ''granted'' the ability to read, create and update descriptions, view draft descriptions, and access digital objects. However, the user has been ''denied'' the ability to delete or publish descriptions. In this scenario, we would like to create a user who can create and update descriptions belonging only to a particular institution and can also publish archival descriptions belonging to the institution.
 
 
 
</li>
 
 
 
[[Image:permissions3.png|500px|right|thumb|Fig.3. Modified permissions for contributor group in edit screen]]
 
 
 
<li>
 
 
 
In order to restrict permissions to descriptions of a particular institution, we need to first deny the permissions to all contributors, and then add them back for the specified institution. We will do the blanket denials in the contributor group edit screen, and later add a user with permissions granted for a particular institution. To deny the permissions in the contributor group, open the edit screen and select Deny for the Create and Update permissions (See fig.3)
 
 
 
</li>
 
 
 
[[Image:permissions4.png|500px|right|thumb|Fig.4. Modified permissions for contributor group in show screen]]
 
 
 
<li>
 
 
 
Click Save. Your show screen should look like the screen in fig.4
 
  
 
</li>
 
</li>
  
[[Image:permissions5.png|500px|right|thumb|Fig.5 Add a new user]]
+
[[Image:singlerep_user02.png|500px|right|thumb|Fig.2.View User permissions screen]]
  
 
<li>
 
<li>
  
Go to admin > users and add a new user as shown in figure 5. Be sure to add the user to the contributor group. Click create when you're done entering the data.
+
Click Edit. Select Permissions by Repository and click Add Repository. Select Repository name from list. Click on Submit. (See fig.3)
  
 
</li>
 
</li>
  
[[Image:permissions6.png|500px|right|thumb|Fig.6]]
+
[[Image:singlerep_user03.png|500px|right|thumb|Fig.3 View permissions by repository.]]
  
 
<li>
 
<li>
  
Click on Archival description permissions. You will see the permissions that are specified in the contributor group, as in fig.6
+
Click on the circles to Grant Permissions to read, create, update, delete, view draft, publish, access master and access reference. (See fig.4)
  
 
</li>
 
</li>
  
[[Image:permissions7.png|500px|right|thumb|Fig.7 Select an archival repository]]
+
[[Image:singlerep_user04.png|500px|right|thumb|Fig.4]]
  
 
<li>
 
<li>
  
Click Edit. Click on the blue "Permissions by archival institution" link and then the "Add archival institution" link. Select the archival institution as in fig.7, then click Submit.
+
Click on Save.
 +
The Administrator can now view the User and their permissions in relation to a specific Repository. (See fig.5)
  
 
</li>
 
</li>
  
[[Image:permissions8.png|500px|right|thumb|Fig.8 Add institution-specific permissions]]
+
[[Image:singlerep_user05.png|500px|right|thumb|Fig.5 View permissions for User]]
  
 
<li>
 
<li>
  
You will now be able to add permissions specific to descriptions belonging to this archival institution. For Create, Update and Publish, select Grant as in fig.8
+
To test your permissions, try logging out and logging back in as the user you created. You should be able to create, edit, delete and publish descriptions belonging to the specified institution only.
 
 
</li>
 
 
 
[[Image:permissions9.png|500px|right|thumb|Fig.9 user view screen showing modified user permissions]]
 
 
 
<li>
 
 
 
Save the record. The screen should show the modified permissions as in fig.9. To test your permissions, try logging out and logging back in as the user you created. You should be able to create, edit and publish descriptions belonging to the specified institution only, and you should not be able to delete any descriptions
 
  
 
</li>
 
</li>
Line 117: Line 71:
 
</div>
 
</div>
  
Go to admin > users > Gene Roddenberry. Instead of clicking on Archival description permissions, click on Authority record permissions. Click Edit. Under ''All authority records'', next to Create and Update, select Deny, then save the record.
+
== Scenario two: Add the ability to translate to a specified language ==
 
 
 
 
== Scenario four: Add the ability to translate to a specified language ==
 
  
 
There are two ways to grant translate permissions to non-administrators:
 
There are two ways to grant translate permissions to non-administrators:
Line 129: Line 80:
  
  
== Scenario five: Remove the ability to view and download master digital objects ==
+
== Scenario three: Remove the ability to view and download master digital objects ==
  
 
<div class="note">
 
<div class="note">
Line 140: Line 91:
  
  
== Scenario six: Add ability to create, update, and delete subject terms ==
+
== Scenario four: Add ability to create, update, and delete subject terms ==
  
 
<div class="note">
 
<div class="note">

Revision as of 16:21, 24 October 2011

Please note that ICA-AtoM is no longer actively supported by Artefactual Systems.
Visit https://www.accesstomemory.org for information about AtoM, the currently supported version.

Main Page > User manual > Administer > Edit permissions

  • You should have two or more archival institutions in your system, with several hierarchical descriptions attached and some digital objects uploaded, in order to fully test the scenarios on this page
  • You can only modify the user's settings if you are logged in as an administrator. After completing the steps in each scenario, log out and log back in as the user you've been creating and modifying in order to see the results of your modifications


Scenario one: In a multi-repository system, add a user who can create, update, and publish archival descriptions belonging to one archival institution only

    When refining user permissions you can begin by creating a User, but do not assign them to a unique User group. Leave this blank and it will automatically assign the User as an authenticated user. (See fig.1)
    Fig.1. Leave group field blank. User automatically becomes an authenticated user.
    In order to restrict permissions to descriptions of a particular institution, we need to go to Admin menu > Users. Select the User you want to restrict to specific repository permissions. (See fig.2)
    Fig.2.View User permissions screen
  1. Click Edit. Select Permissions by Repository and click Add Repository. Select Repository name from list. Click on Submit. (See fig.3)
  2. Fig.3 View permissions by repository.
  3. Click on the circles to Grant Permissions to read, create, update, delete, view draft, publish, access master and access reference. (See fig.4)
  4. Fig.4
  5. Click on Save. The Administrator can now view the User and their permissions in relation to a specific Repository. (See fig.5)
  6. Fig.5 View permissions for User
  7. To test your permissions, try logging out and logging back in as the user you created. You should be able to create, edit, delete and publish descriptions belonging to the specified institution only.

Scenario two: Add the ability to delete the archival descriptions of the specified institution

Remember that a user in the contributor group does not automatically have the ability to delete any records. To add the ability to delete archival descriptions belonging to the archival institution the user can currently edit and update, go to admin > users > Gene Roddenberry. Click Archival description permissions. Click Edit. For the specified institution, change the Delete permission to Grant.


Scenario three: Remove the ability to create and update authority records

Permissions for authority records can be refined in some of the same ways they can be refined for archival descriptions. In a multi-repository setting it may be desirable to prevent users from creating and/or updating authority records, because one authority record may be linked to archival descriptions belonging to more than one archival institution.

Users belonging to the contributor group automatically inherit the ability to create and update authority records.

Scenario two: Add the ability to translate to a specified language

There are two ways to grant translate permissions to non-administrators:

  • Make the user a translator by adding him to the translator group (the same way that you made Gene Roddenberry a contributor). This means that he will be able to translate to any language.
  • Instead of making the user a translator, which would allow him to translate to any language, add a language to which a user can translate. This means that he will be able to translate only to the specified language, and only those archival descriptions and authority records he is allowed to update. In this scenario, we will add the ability of the user to translate to Dutch.

Go to admin > users > Gene Roddenberry. You should be in looking at the View user profile screen; if not, click Profile (to the left of Archival description permissions). Click Edit, then click on the blue "Access control" link. In allowed languages for translation, select Dutch. Click Save. The user will now be able to translate from any source language to Dutch. Note that the list of languages is derived from the languages added in the settings menu. See add/remove languages. Note also that you can add more languages from this list as needed.


Scenario three: Remove the ability to view and download master digital objects

Users belonging to the contributor group automatically inherit the ability to view and download master digital objects.

Go to admin > users > Gene Roddenberry. Click on Archival description permissions. Click Edit. Under All archival descriptions next to Access master click Deny. Save the record. This will allow the user to view thumbnail and reference display copies of digital objects, but not to view or download the master objects. Note that if you do not wish to have any users belonging to the Contributor group viewing or downloading masters digital objects, deny permission for this activity at the level of the group - i.e. go to admin > groups > contributor and make the change at that level instead of the level of the individual user.


Scenario four: Add ability to create, update, and delete subject terms

Users belonging to the contributor group do not automatically inherit the ability to create, update, and delete taxonomy terms. You can change these permissions for either the contributor group or an individual user. In this case, we will add the ability to create, update and delete subject terms to our individual user.

Go to admin > users > Gene Roddenberry. Click on Taxonomy permissions (next to Authority record permissions). Click Edit. Click the blue link "Permissions by taxonomy", then click "Add taxonomy". Select Subjects as the taxonomy name from the auto-complete list. Next to Create, Update and Delete select Grant, then save the record. The user should now be able to create, update and delete subject terms but not other kinds of taxonomy terms.